CVE-2021-33655Out-of-bounds Write in Kernel

CWE-787Out-of-bounds Write50 documents10 sources
Severity
6.7MEDIUMNVD
OSV5.5
EPSS
0.0%
top 93.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateFeb 14

Description

When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages13 packages

NVDlinux/linux_kernel< 5.19+1
Debianlinux/linux_kernel< 5.10.127-2+3
Ubuntulinux/linux_kernel< 4.15.0-193.204+3
CVEListV5linux/linux_kernel5.18 5.19.0-rc1

Also affects: Debian Linux 10.0, 11.0

Patches

🔴Vulnerability Details

24
OSV
CVE-2021-33655: In fbcon_set_font() of fbcon2023-03-01
OSV
linux-ibm vulnerabilities2022-10-14
OSV
linux-gcp-5.4 vulnerabilities2022-10-06
OSV
linux-intel-iotg vulnerabilities2022-10-04
OSV
linux-gke vulnerabilities2022-10-04

📋Vendor Advisories

25
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
CISA ICS
Siemens SIMATIC S7-1500 TM MFP Linux Kernel2023-06-15
Android
CVE-2021-33655: Frame Buffer2023-03-01
Ubuntu
Linux kernel (IBM) vulnerabilities2022-10-14
Ubuntu
Linux kernel (GCP) vulnerabilities2022-10-06